PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-3500HighKeylime: Keylime: unhandled exceptions could lead to invalid attestation statesCVE-2022-3697Highansible: Ansible leaks password to logsCVE-2022-3363Criticalrdiffweb: Rdiffweb subject to Business Logic ErrorsCVE-2022-39348Mediumtwisted: Twisted vulnerable to NameVirtualHost Host header injectionCVE-2022-39286Highjupyter-core: Execution with Unnecessary Privileges in JupyterAppCVE-2022-43766Highorg.apache.iotdb:flink-tsfile-connector: Apache IoTDB subject to ReDOS with Java 8CVE-2022-39327Highazure-cli: Improper Control of Generation of Code ('Code Injection') in Azure CLICVE-2022-3644Mediumpulp-ansible: Plaintext storage of tokens in pulp_ansibleCVE-2022-3327Criticalrdiffweb: Rdiffweb is missing authentication for critical functionCVE-2022-37298CriticalShinken: Shinken Solutions Shinken Monitoring vulnerable to Incorrect Access ControlCVE-2022-3607MediumOctoPrint: OctoPrint vulnerable to Special Element InjectionCVE-2022-41547Highmobsf: MobSF allows attackers to read arbitrary files via a crafted HTTP requestCVE-2022-41323Highdjango: Django denial-of-service vulnerability in internationalized URLsCVE-2022-3439Criticalrdiffweb: Missing rate limit on rdiffwebCVE-2022-3457Criticalrdiffweb: Origin Validation Error in rdiffwebCVE-2022-3456Mediumrdiffweb: Missing rate limit on rdiffwebCVE-2022-42906Highpowerline-gitstatus: Powerline Gitstatus vulnerable to arbitrary code executionCVE-2022-36070Highpoetry: Poetry vulnerable to Untrusted Search Path leading to Local Code Execution on WindowsCVE-2022-42731Highdjango-mfa2: django-mfa2 vulnerable to MFA Replay attackCVE-2022-3438Mediumrdiffweb: rdiffweb vulnerable to Open RedirectCVE-2022-41672Highapache-airflow: Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or APIGHSA-8R99-H8J2-RW64Mediumtwisted: Twisted vulnerable to HTTP Request Smuggling AttacksCVE-2021-23385MediumFlask-Security: Flask-Security vulnerable to Open RedirectCVE-2020-26269Hightensorflow: TensorFlow vulnerable to heap out of bounds read in filesystem glob matchingCVE-2022-3273Highrdiffweb: rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks

Stop the waste.
Protect your environment with Kodem.